What happened
On 12 August 2026, the White House issued a presidential memorandum creating a federally controlled programme for private-sector cyber operations against foreign cyber-enabled transnational criminal organisations. The programme may authorise Participating Companies to conduct Cyber Surveillance Operations and Cyber Effects Operations under federal control and oversight. The National Coordination Center, operating through the Homeland Security Task Force, is directed to create and manage the programme with executive leadership from the Department of Justice and Department of Homeland Security.
Participating Companies may receive threat information from private entities and government bodies for the purpose of proposing responsive operations to the National Coordination Center. Participation is described as voluntary, and operations remain under US Government direction, control and authority. The text therefore establishes a controlled government programme rather than a general right for companies to conduct independent retaliation against suspected attackers.
In the memorandum, the programme’s executive directors must submit a status report within 180 days and annually thereafter. The cited White House documents did not publish a list of approved companies or operational targets. Independent reporting characterised the policy as a significant expansion of private participation in offensive cyber activity. Attribution posture: The memorandum addresses categories of foreign cyber-enabled transnational criminal organisations and does not attribute a specific incident or actor.
Why this matters now
The memorandum changes the policy boundary around private-sector offensive capability without granting ordinary enterprises unrestricted permission to retaliate. Security leaders may encounter new requests to share threat information, support vetted providers or assess participation. Those decisions engage legal authority, evidence handling, privacy, contractual restrictions, insurance, cross-border data transfer and operational-risk questions that cannot be delegated to a threat-intelligence team alone.
The immediate enterprise issue is governance, not capability acquisition. Companies that are not programme participants still need rules for responding to government or supplier requests connected to an operation. Organisations considering participation need stronger separation of duties, executive authorisation, target validation, auditability and incident-containment boundaries than normal defensive testing requires.
The decision for security leaders
Place programme participation and related information sharing under a joint CISO, general counsel and executive-risk decision. Defensive threat intelligence should not drift into operational support through informal analyst relationships.
Define what evidence may be shared, which jurisdictions and contracts constrain it, how personal data is minimised, and how chain of custody is preserved before any external engagement.
Require participating suppliers to disclose authority, scope, oversight and containment boundaries. A vendor’s programme status should not substitute for the organisation’s own legal and risk assessment.
Evidence of closure
- An approved policy defines who may discuss or support government-directed cyber operations.
- A legal memorandum records the organisation’s authority, restrictions and prohibited activities.
- A data-sharing standard defines approved evidence, minimisation and chain-of-custody controls.
- Supplier contracts document whether offensive cyber activity is permitted, excluded or subject to approval.
The Security.io assessment
The memorandum is authoritative and materially changes US policy, but implementation details remain incomplete. It creates a programme and governance mechanism; it does not establish that any private company has been approved or that any operation has begun. The cited White House documents did not publish a list of approved companies or operational targets.
Attribution posture: The memorandum addresses categories of foreign cyber-enabled transnational criminal organisations and does not attribute a specific incident or actor. Security.io therefore treats this as a governance development rather than evidence about a particular campaign, victim or criminal group.
The near-term CISO value is boundary setting. Enterprises should be prepared for new public-private operating models while retaining clear prohibitions on unilateral action, unapproved intelligence disclosure and supplier activity that could create legal, diplomatic or operational exposure.
Questions for the morning meeting
- Does the organisation have an approved boundary for sharing threat intelligence that could support government-directed operations?
- Who can authorise discussions about programme participation, and which board committee requires notification?
- Can legal, privacy and security teams distinguish voluntary federal participation from independent corporate hack-back activity?